insecure-source-code-management
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as an offensive security testing guide, but its actual footprint is high-risk because it teaches an AI agent to probe for and recover sensitive source-control and config exposures, including secrets. There is no direct credential exfiltration to attacker-controlled endpoints and no installer payloads in the skill text, so this is not confirmed malware; however, it is a security/exploit-oriented skill with transitive skill-loading and optional third-party tool use, making it unsuitable for general-purpose agent deployment.
Confidence: 89%Severity: 78%
Audit Metadata